Content Security Policy combined with HTTP to HTTPS redirection can be used by malicious server to verify whether a known site is within a user's browser history. This vulnerability affects Firefox < 50.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-9071.json"
[ { "events": [ { "introduced": "0" }, { "fixed": "50.0" } ] } ]